Microsoft has released a major Sysinternals update, which fixes several bugs. In addition to standard bug fixes, the company has updated System Monitor, Process Monitor, among other major changes. Windows Sysinternals hosts system utilities and technical information to manage, troubleshoot, and diagnose Windows systems and applications.
Windows Sysinternals get a major update
The September 17, 2020 update to System Monitor brings support for capturing clipboard operations. The System Monitor (Sysmon v12.0) update will enable incident responders to retrieve attacker Remote Desktop Protocol (RDP) file and command drops including “originating remote machine IP addresses.”
In addition to Sysmon v12.0, the Windows Sysinternals update comprises Process Monitor v3.60 update. In a nutshell, well, Process Monitor utility keep track of a process file, network, and registry activity.
Describing the update, Microsoft had this to say:
“This update to Process Monitor, a utility that logs process file, network and registry activity, adds support for multiple filter item selection, as well as decoding for new file system control operations and error status codes.”
The Windows Sysinternal update also marks the release of ProcDump v10.0. ProcDump is nothing but a command-line tool for monitoring an application for CPU spikes and accordingly generating crash dumps during a spike. The utility also helps administrators and developers determine the cause of the spike.
The ProcDump v10.0 update has added support for dump cancellation and CoreCLR processes. As part of the update, the following is the full list of tools that have been newly ported to and are now available for ARM64:
- AdInsight v1.2
- AutoLogon v3.1
- Autoruns v13.98
- ClockRes v2.1
- DebugView v4.9
- DiskExt v1.2
- FindLinks v1.1
- Handle v4.22
- Hex2Dec v1.1
- Junction v1.07
- PendMoves v1.02
- PipeList v1.02
- Procdump v10.0
- Process Explorer v16.32
- RegDelNull v1.11
- RU v1.2
- Sigcheck v2.8
- Streams v1.6
- Sync v2.2
- VMMap v3.26
- WhoIs v1.21
- ZoomIt v4.52
You can now download all ARM64 tools in a single download, courtesy of Sysinternals Suite for ARM64.